Legal

Privacy Policy

Last updated: May 31, 2026

This Privacy Policy explains how Host Agency AI, Inc. (“Host Agency AI”, “we”, “us”) collects, uses, discloses, and safeguards your information when you use our website and platform (the “Service”). By using the Service you agree to the practices described here.

1. Who we are

Host Agency AI, Inc. is the data controller for personal data processed about visitors and account holders. For personal data that our customers (agencies) process about their own clients using the Service, the customer is the controller and Host Agency AI acts as a processor under our Data Processing Addendum.

2. Information we collect

Information you provide

  • Account data — name, email, password hash, organization name, and role.
  • Workspace content — clients, projects, tasks, time entries, invoices, documents, and messages you create.
  • Billing data — plan, subscription status, and payment identifiers (processed by our payment provider; we do not store full card numbers).
  • Support communications — messages you send us.

Information collected automatically

  • Usage data — pages viewed, features used, and actions taken.
  • Device & log data — IP address, browser type, and timestamps.
  • Cookies — see our Cookie Policy.

3. How we use information

  • To provide, maintain, and improve the Service.
  • To authenticate users and secure accounts.
  • To process payments and manage subscriptions.
  • To provide AI assistant features you invoke (your prompts and the relevant workspace data are sent to our AI subprocessor solely to generate responses; they are not used to train third-party models).
  • To send transactional emails (invoices, invitations, reminders) and important service notices.
  • To detect, prevent, and address fraud, abuse, and security incidents.
  • To comply with legal obligations.

4. Legal bases (EEA/UK)

Where applicable, we rely on: performance of a contract, our legitimate interests (securing and improving the Service), your consent (e.g. non-essential cookies), and compliance with legal obligations.

5. How we share information

We do not sell your personal data. We share information with:

  • Subprocessors who help us operate the Service (hosting, database, payments, email, AI). See our Subprocessors list.
  • Within your organization — workspace content is visible to other members per their role.
  • Legal & safety — when required by law or to protect rights, safety, and property.
  • Business transfers — in connection with a merger, acquisition, or asset sale, subject to this Policy.

6. Data retention

We retain personal data for as long as your account is active and as needed to provide the Service. After account closure we delete or anonymize data within a commercially reasonable period, except where retention is required for legal, accounting, or security purposes.

7. International transfers

Your data may be processed in countries other than your own. Where required, we use appropriate safeguards such as Standard Contractual Clauses.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object or withdraw consent. To exercise these rights, contact privacy@hostagencyai.com. You may also lodge a complaint with your local data protection authority.

9. Security

We implement technical and organizational measures to protect your data, including encryption in transit and at rest. No method of transmission or storage is 100% secure.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect their data.

11. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified via the Service or email. Continued use after changes constitutes acceptance.

12. Contact

Host Agency AI, Inc., [Registered Address]. Email: privacy@hostagencyai.com.